Automated Detection of Configuration-Specific Security Vulnerabilities via Patch Analysis
We study how security patches in highly configurable C/C++ systems map onto the space of compile-time variants. We formalize the Vulnerability Impact Condition (VIC)—a Boolean predicate over configuration options that denotes all variants that contained the original flaw—and introduce PatchLens, a purely static technique that recovers VICs by aligning AST-level patch hunks with source-level presence conditions and resolving file inclusion via lightweight build system analysis. Evaluating PatchLens on 1,193 Linux kernel, 290 FFmpeg, and 99 PHP patches, we compute precise, human-readable VICs without the need to compile any system variant. The resulting predicates are compact (avg. 2.09 variables for Linux, 3.30 for FFmpeg, 0.95 for PHP) and show that only a small fraction of vulnerabilities are system-wide, which carry higher CVSS scores; meanwhile, CVE texts almost never encode the required options (≈1% average recall), motivating automated enrichment of CVE descriptions with VICs. PatchLens and the accompanying dataset enable immediate applications in CI (variant-aware triage and test selection), targeted sampling and fuzzing, and feature risk scoring, offering a scalable, explainable path to vulnerability assessment in highly configurable software.
Thu 9 JulDisplayed time zone: Eastern Time (US & Canada) change
14:00 - 15:30 | Vulnerability 2Research Papers / Industry Papers at MB 3.445 Chair(s): Mahmoud Alfadel University of Calgary | ||
14:00 20mTalk | VulKey: Automated Vulnerability Repair Guided by Domain-Specific Repair Patterns Research Papers Jia Li The Chinese University of Hong Kong, Zhuangbin Chen Sun Yat-sen University, Yuxin Su Sun Yat-sen University, Michael Lyu The Chinese University of Hong Kong Pre-print | ||
14:20 20mTalk | Thought is All You Need: Smart Contract Vulnerability Detection with Thought-Augmented Large Language Model Research Papers Chaoyuan Peng Zhejiang University, Muhui Jiang BlockSec, Yajin Zhou The Chinese University of Hong Kong, Lei Wu Zhejiang University | ||
14:40 20mTalk | Mitigating Implicit Inconsistencies in Patch Porting Industry Papers Shengyi Pan Zhejiang University, Zhongxin Liu Zhejiang University, Jiayuan Zhou Huawei, Xing Hu Zhejiang University, Xin Xia Zhejiang University, Shanping Li The State Key Laboratory of Blockchain and Data Security, Zhejiang University | ||
15:00 20mTalk | Automated Detection of Configuration-Specific Security Vulnerabilities via Patch Analysis Research Papers Felipe Paixão Federal University of Bahia (UFBA), Eduardo Almeida Federal University of Bahia (UFBA), Joanna C. S. Santos University of Notre Dame, Paulo Anselmo da Mota Silveira Neto Federal Rural University of Pernambuco, Recife, Pernambuco, Daniel Sadoc Menasche Federal University of Rio de Janeiro, Gustavo B. Figueiredo Federal University of Bahia (UFBA) DOI Pre-print | ||